Записи OneLogin
11 опубликованных записей вендора onelogin.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 90,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-347 Improper Verification of Cryptographic Signature5
- CWE-287 Improper Authentication2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-798 Use of Hard-coded Credentials1
- CWE-91 XML Injection (aka Blind XPath Injection)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2025-25292Эксплойта нет | Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)omniauth · omniauth saml · CWE-347 | Критическая9,3 | — | 65,1 % | 12 мар. 2025 г. |
43В плане | CVE-2025-25291Proof of concept | ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)omniauth · omniauth saml · CWE-347 | Критическая9,3 | — | 20,6 % | 12 мар. 2025 г. |
42В плане | CVE-2024-45409Proof of concept | The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectoronelogin · ruby-saml · CWE-347 | Критическая9,8 | — | 10,7 % | 10 сент. 2024 г. |
40В плане | CVE-2017-11427Proof of concept | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalonelogin · pythonsaml · CWE-287 | Критическая9,8 | — | 4,7 % | 17 апр. 2019 г. |
40В плане | CVE-2017-11428Эксплойта нет | Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalonelogin · ruby-saml · CWE-287 | Критическая9,8 | — | 2,4 % | 17 апр. 2019 г. |
39Наблюдать | CVE-2015-20108Эксплойта нет | xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not useonelogin · ruby-saml · CWE-77 | Критическая9,8 | — | 1,3 % | 27 мая 2023 г. |
37Наблюдать | CVE-2025-66567Эксплойта нет | ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)onelogin · ruby-saml · CWE-347 | Критическая9,3 | — | 0,4 % | 9 дек. 2025 г. |
37Наблюдать | CVE-2025-66568Эксплойта нет | ruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validationonelogin · ruby-saml · CWE-347 | Критическая9,3 | — | 0,2 % | 9 дек. 2025 г. |
31Наблюдать | CVE-2016-10928Эксплойта нет | The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.onelogin · onelogin saml sso · CWE-798 | Высокая7,5 | — | 1,7 % | 22 авг. 2019 г. |
30Наблюдать | CVE-2025-25293Эксплойта нет | ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responsesomniauth · omniauth saml · CWE-400 | Высокая7,7 | — | 1,5 % | 12 мар. 2025 г. |
30Наблюдать | CVE-2016-5697Эксплойта нет | Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.onelogin · ruby-saml · CWE-91 | Высокая7,5 | — | 1,2 % | 23 янв. 2017 г. |
- CVE-2025-2529257В плане
Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
КритическаяCVSS 9,3Эксплойта нетEPSS 65 %omniauth · omniauth saml12 мар. 2025 г.
- CVE-2025-2529143В плане
ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
КритическаяCVSS 9,3Proof of conceptEPSS 21 %omniauth · omniauth saml12 мар. 2025 г.
- CVE-2024-4540942В плане
The Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selector
КритическаяCVSS 9,8Proof of conceptEPSS 11 %onelogin · ruby-saml10 сент. 2024 г.
- CVE-2017-1142740В плане
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
КритическаяCVSS 9,8Proof of conceptEPSS 5 %onelogin · pythonsaml17 апр. 2019 г.
- CVE-2017-1142840В плане
Multiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %onelogin · ruby-saml17 апр. 2019 г.
- CVE-2015-2010839Наблюдать
xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not use
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %onelogin · ruby-saml27 мая 2023 г.
- CVE-2025-6656737Наблюдать
ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %onelogin · ruby-saml9 дек. 2025 г.
- CVE-2025-6656837Наблюдать
ruby-saml Libxml2 Canonicalization errors can bypass Digest/Signature validation
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %onelogin · ruby-saml9 дек. 2025 г.
- CVE-2016-1092831Наблюдать
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %onelogin · onelogin saml sso22 авг. 2019 г.
- CVE-2025-2529330Наблюдать
ruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %omniauth · omniauth saml12 мар. 2025 г.
- CVE-2016-569730Наблюдать
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %onelogin · ruby-saml23 янв. 2017 г.